Privacy Policy
This Privacy Policy describes how Chanho Chung (hereinafter “Service Provider”), an individual developer, collects, uses, and protects your information when you use the Byulnuri applications for Android and desktop (hereinafter “Application”) and the Byulnuri website at byulnuri.com and its subdomains (hereinafter “Website”). The Application and the Website are provided “AS IS” as a free service.
Service Provider and Privacy Contact
- Service Provider: Chanho Chung (individual developer)
- General support: support@byulnuri.com
- Privacy contact: Chanho Chung, hello@chungchan.dev
Scope of This Policy
This Privacy Policy covers the products operated by the Service Provider under the “Byulnuri” name:
- The Byulnuri Application for Android and desktop, which hosts Minecraft Bedrock multiplayer sessions (as LAN servers and, where offered, cloud servers) and provides the social platform (profiles, communities, and chat)
- The Byulnuri Website at byulnuri.com and its subdomains, which provides marketing/information pages and a signed-in web client (account registration, profile and settings management, public profiles, server discovery, and real-time presence)
Because the Application and the signed-in Website are two clients for the same Byulnuri account, most account, social, community, and moderation data described in Section 1 is collected wherever you use a Byulnuri account, regardless of client. Where a section applies to only one client, it is labeled accordingly. Section 2 additionally describes technologies specific to the Website (cookies, browser storage, and web analytics).
1. Information We Collect: Account and Platform
This section applies wherever you use a Byulnuri account: in the Android app, the desktop app, or the signed-in Website. It is organized by the kind of data we process rather than by product feature.
1.1 Account Information
When you sign in, we collect and store the following information through our self-hosted sign-in system. Sign-in via Google OAuth is supported as an upstream provider.
| Item | Purpose | Retention |
|---|---|---|
| Email address (received from Google OAuth via our sign-in system) | Account identification and login | Until account deletion |
| Internal account identifier | Stable account reference | Until account deletion |
| Username and display name | Public-facing identity in profiles, servers, chat, and lists | Until account deletion |
| Profile bio (optional, free text) | Public-facing detail shown on your user profile | Until you clear it or delete your account |
| Profile picture / avatar (optional) | Public-facing avatar shown on your profile, in servers, chat, and lists | Until you remove it or delete your account |
| Account status (e.g., suspension start and end times) | Enforce and display any account restriction (see Section 1.8) | Retained as moderation history |
Your sign-in tokens are stored securely and are not accessible to web-page scripts (see Section 2.2 and Section 9).
Username, display name, bio, and avatar are visible to other users wherever you appear: on your public profile, in servers you host or join, in social lists (followers, following, “starlinks”), and in any community (galaxy) channels you participate in.
Username changes. When you change your username, we retain a record of the change (the previous and new username, with a timestamp). This record enforces a change-frequency limit (currently about 14 days between changes) and serves as an audit history.
1.2 Automatically Collected Data (Analytics and Crash Reporting)
The Application and the Website (including public Website pages) use our self-hosted analytics system. The Android and desktop Application also uses our self-hosted crash-reporting system; crash reporting is not currently used on the Website. Together these collect:
| Item | Purpose | Retention |
|---|---|---|
| IP address | Anti-abuse and approximate location (country / region / city) | Not stored by our analytics, discarded after request-time processing |
| Approximate location (country, region, city) inferred from your IP address | Regional analytics | Indefinite (subject to change with notice) |
| Device / browser characteristics (such as brand, model, operating-system version, screen size, app or browser version, and mobile carrier) | Analytics, debugging, compatibility tracking | Indefinite (subject to change with notice) |
| Anonymous analytics profile ID (stored on your device or in browser storage) | Cross-session analytics linking | Until app uninstall, clear data, browser-storage clear, or logout |
| Identifier used to distinguish anonymous sessions | Anonymous analytics | Rotated daily |
| Application usage events (e.g., screen views, navigation, button clicks, hosting state changes, follow/join/invite actions) and crash reports | Bug fixing and product improvement | Indefinite (subject to change with notice) |
Once you sign in, subsequent analytics events are associated with your account. On the Application, your email address, display name, and username are also associated with your analytics profile; on the Website, your analytics profile is linked by your account identifier and your display name, username, and avatar (not your email). Crash reports may contain device and application diagnostics, error details, and incidental application state; such information can be personal data even when collected incidentally, and is used only to diagnose and fix faults.
1.3 Device Identifiers and Push Notification Tokens
- Device identifier. The Application and the Website generate a random device identifier the first time you use them. On the Application it is stored on the device and persists across sign-ins; on the Website it is stored in browser storage. It is a software-generated value, not a hardware identifier; we do not access your IMEI, MAC address, serial number, or advertising ID for this purpose. It is used to distinguish your device for presence, push notifications, connection identification, participant blocking, security, and moderation.
- Push notification tokens. If you enable notifications, we store a push registration token (from Google Firebase Cloud Messaging), together with your device identifier and platform, so we can deliver notifications to your device. Push messages may include a sender’s display name, a short preview of message text, avatar references, and identifiers used to open the right screen. Tokens are removed when you sign out, and stale or invalid tokens are cleared.
1.4 Messaging and Communities
The platform includes communities (“galaxies”), each containing text “channels,” as well as one-to-one direct messages (DMs). When you use these features, we store on our servers: the galaxies and channels you create (name, description, avatar, and visibility setting); membership records (which galaxies you belong to, your role, and when you joined); the chat messages and direct messages you send (text content, timestamps, and edit/deletion metadata); mentions you send or receive (@everyone/@here, user mentions, and role mentions); your read state (the most recent message you have read in each channel, synced across your devices); and community moderation records (such as galaxy-level bans, with a reason and who issued them).
Storage and access. Message content, including chat and direct-message text, is stored in readable form on our servers and is not end-to-end encrypted. We can technically access it where necessary to operate the service, respond to reports or abuse, enforce our terms, or comply with the law.
Visibility. Content in a public galaxy can be read by anyone, including people browsing without signing in; content in a private galaxy is limited to its members; and direct messages are limited to the two participants. Treat anything you post as visible to other people.
Deletion and retention. You can delete messages you authored, and a galaxy owner can delete messages within their galaxy. This data is kept until the message, channel, galaxy, or DM thread is deleted (deleting a channel or galaxy removes the messages it contains); read state and mention records are kept until the channel is deleted or you delete your account. See Section 7 for how residual data is handled.
1.5 Social Connections and Presence
Social connections. When you use the social features, we store on our servers: your follow relationships (who you follow and who follows you) and “starlinks” (mutual follows); activity records (such as following someone, forming a starlink, hosting a server, or changing your username); and the notifications you receive (a new follower, a starlink forming, a followed user hosting a server, or a server invitation) with their read state. Your followers, following, and starlinks lists, and a filtered subset of your activity, are publicly visible on your profile. Follow relationships and activity records are kept until you unfollow (where applicable) or delete your account; notifications are kept until aged out, cleared, or you delete your account.
Presence (online status). When you are signed in, we report real-time presence so other users can see whether you are reachable: your status (for example, online, idle, or do-not-disturb) and a coarse description of the device you are connected from (for example, the platform or operating-system family). Presence is shared in real time with users who can see you; it is held only temporarily on our servers for the duration of your active session, is not written to long-term storage, and is cleared when your session ends.
1.6 Hosting Minecraft Servers (LAN and Cloud)
You can host multiplayer Minecraft Bedrock sessions in two ways: a LAN server, where the Application relays traffic between remote players and the Minecraft world running on your own device; and a cloud server, where we run a Minecraft Bedrock server for you. Both involve processing data about the players who join, in addition to your own account data.
Data about players who join. When a player joins your LAN server or cloud server, we process their Minecraft identity information (such as Xbox User ID, gamertag, and Minecraft identity/ID), basic device and game-version information, and their network (IP) address. For a LAN server, the Application reads this from each joining player’s Xbox sign-in and forwards it to your Minecraft world; it is mostly held only for the duration of that player’s session, except where it is stored for chat relay, moderation, or blocking (described below). Verifying a player’s Xbox sign-in may involve contacting Microsoft/Xbox servers. For a cloud server, this data is recorded in per-server player records (last-seen identity and last-known IP, plus recent session times and the join code used) that are visible only to you as the server owner; session history is retained approximately 90 days, and older records are pruned.
Chat relay (built-in). Relaying in-game activity to a Byulnuri community channel is a standard, required part of hosting a LAN server or a cloud server; it is not optional. While you host, the following events from players in your world (including players who joined via a share link and have never installed the Application or signed in) are stored on our servers as channel messages, each recorded with the player’s Minecraft username and Xbox identity/XUID: in-game chat messages, join and leave events, and death events (including the death message text). Server-generated status notices (recorded with the server’s name when hosting starts or stops) are also stored. You choose which channel the relay connects to (for example, you can create a private galaxy and link the relay to a channel there), but you cannot turn the relay off while hosting. Because players cannot edit or delete these messages themselves, they remain as channel history until you or a galaxy owner deletes the channel or galaxy. You are responsible for making players in your world aware that their in-game chat and events are relayed to, and stored in, a Byulnuri community channel.
Blocking players. As a host you can block a player from your server. To enforce the block, we store, until you remove it: the player’s device metadata (device identifier, OS, model, game version), their Minecraft identity, Xbox User ID (XUID), and username, their IP address (when you block by network address), and an optional free-text block reason. Use blocking only for legitimate moderation, and do not retain blocks indefinitely without justification.
Cloud server specifics. For a cloud server you own, we also store the server’s name and configuration (game settings), lifecycle and billing metadata (see Section 1.7), and references to world backups. Your server’s Minecraft world (including all in-world content and the game’s per-player data, such as inventories and positions) is backed up to third-party cloud storage (Cloudflare); automatic backups are rotated with up to 7 daily, 4 weekly, and 3 monthly copies, manual backups are kept until you delete them, and a small number of pre-restore safety copies are kept. As the owner you can view the live server console output (which can include the game’s own join/leave and command log lines); it is shown to you live and is not stored long-term. You may also grant in-game operator (“OP”) privileges to a Byulnuri account, an Xbox User ID, or a device; these grants are stored with the server.
Data created through hosting is also used for safety and moderation as described in Section 1.8.
1.7 Stardust (In-App Currency) and Rewarded Ads
The platform includes an in-app virtual currency (“Stardust”), used for features such as running cloud-hosted servers.
- Balance and ledger. We store your current Stardust balance and a transaction history (each entry records the amount, the resulting balance, and the reason, such as an administrative grant or revocation, cloud-server usage charges, a reward, or an adjustment). Transaction history is retained as a financial audit trail.
- Rewarded ads. You may choose to watch a rewarded advertisement provided by Google AdMob. Advertising is loaded only when you choose to watch an ad. For reward verification, the Application sends Google a Byulnuri account identifier and a one-time code; after you complete the ad, Google sends our servers that account identifier, the one-time code, and an AdMob transaction identifier, which we store to credit the reward and prevent duplicate or fraudulent claims. Google AdMob also collects advertising identifiers, device information, and ad-interaction data under Google’s own policies (see Section 4 and Section 6).
1.8 Safety, Moderation, and Connection Tracking
To operate the service safely and enforce our terms, the platform keeps connection records and moderation records. These features are highly privacy-sensitive; access is restricted to authorized staff.
Connection tracking. When you connect to the service in ways that reveal your network or Minecraft identity (for example, joining a LAN server or a cloud-hosted server, or connecting from the app), we may keep a connection record containing:
- Your network (IP) address
- Device identifiers (your operating-system device identifier and, for Minecraft connections, the Minecraft device identifier)
- Minecraft identity information (such as Xbox User ID, identity ID, and gamertag), including whether that identity has been verified
- Context such as the LAN server, cloud server, or channel involved
Purpose. These records let authorized staff investigate abuse, detect ban evasion, and enforce moderation. Retention. Raw IP addresses in these records are automatically deleted after a retention period (currently 90 days) unless kept as part of an active moderation record; the non-IP identity information is retained longer to support moderation.
Staff access is tiered. Access is limited to staff who hold specific permissions: some moderation staff can see a user’s linked Minecraft identities without raw IP addresses, while viewing raw IP/network history requires a separate, higher permission.
Punishments. When staff take action against an account, an IP address, or a Minecraft identity, we create a punishment record. This can be a warning, an account suspension/ban, an IP ban, or a Minecraft-identity ban, and records the type of action and its target, the reason, the staff member who issued it, the time and any expiry, and whether it was later voided (and by whom, and why).
Punishment records are retained as a lasting moderation history: voiding a punishment does not delete it, and it is not deleted when the associated account is deleted. Because IP bans and Minecraft-identity bans target an identifier rather than an account, they can remain enforceable even after the associated account is deleted. If your account is permanently banned, your public profile fields (username, display name, bio, avatar, roles) are hidden from other users while the ban is in effect. You can view the punishments that apply to you from within your own account.
Evidence. Staff may attach evidence files (for example, screenshots) to a punishment. These files are stored privately in third-party cloud storage (Cloudflare) and are accessible only to authorized staff. Evidence is kept with its punishment record as part of the moderation history; voiding a punishment does not delete it, and it may remain after the associated account is deleted.
Staff roles. Staff accounts carry role and permission assignments that determine which moderation tools and data they can access. These assignments (and who granted them) are stored on the account.
2. Information We Collect: Website
Beyond the account and platform data in Section 1, the Website uses the following browser-side technologies.
2.1 Account and Profile Features
The signed-in Website is a full client for your Byulnuri account. Through it you can register a username, edit your profile (display name and bio), upload or remove an avatar, browse public profiles and the server directory, and appear online through real-time presence. Data you create or submit through these features is handled as described in Section 1.
The Website’s public marketing/information pages (such as the landing page and legal pages) do not require sign-in and do not have public contact forms, search inputs, or public content-submission forms; contact is via the email address shown in the footer.
2.2 Cookies and Local Storage
The Website uses the following first-party cookies and browser storage:
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
auth_session | Cookie | Keeps you signed in; holds your session securely and is not readable by page scripts | Up to 30 days |
bn_oidc_tx | Cookie | Temporary value used during sign-in to protect the login process | 10 minutes |
lang | Cookie | Remembers your interface language (en / ko) | Up to ~400 days |
device_id | Local storage | Random device identifier for real-time presence and push registration (see Section 1.3) | Until you clear it |
| Appearance preferences (mode and theme) | Local storage | Remember your light/dark and theme selection | Until you clear it |
Our analytics provider (OpenPanel, self-hosted; see Section 2.3) also sets its own cookies and/or browser storage to distinguish anonymous visitors and maintain session continuity.
2.3 Website Analytics and Session Replay
The Website uses our self-hosted analytics system (OpenPanel) to collect:
| Item | Purpose | Retention |
|---|---|---|
| IP address | Approximate location (country / region / city) and anti-abuse | Not stored by our analytics, discarded after request-time processing |
| Approximate location (country, region, city) inferred from your IP address | Regional analytics | Indefinite (subject to change with notice) |
| Browser and device characteristics (browser type and version, operating system, screen resolution) | Compatibility and UI analytics | Indefinite (subject to change with notice) |
| Page views, navigation paths, outgoing link clicks, and specific in-page actions (such as clicking to join a server or accept an invite) | Product analytics | Indefinite (subject to change with notice) |
| Session replays: mouse movement, clicks, scrolls (input fields are masked) | UX debugging | Up to 30 days, then deleted automatically |
Session replay is active on the production Website (not in local development), and all form-input values are masked in replays. When you are signed in, analytics events are linked to your account by your account identifier (and your display name, username, and avatar); the Website does not send your email address to analytics. Anonymous visitors are tracked with a provider-generated visitor identifier.
2.4 IP Addresses (Website)
The Website’s server processes your IP address briefly to limit repeated sign-in attempts (to prevent abuse). This is done in memory and is not written to disk or logged by the Website. When you click to join a LAN server or cloud server from the Website, your browser sends the join request to our game infrastructure, which receives your IP address so it can connect you to the game (see Section 3 and Section 1.8).
3. Location Information
The Application does not collect precise (GPS-level) location information, and does not request location, camera, microphone, or contacts permissions.
However, the Service Provider’s servers and analytics systems automatically receive your IP address as a normal part of any network request. IP addresses can be used to estimate approximate location at the country, region, or city level and, for game connections, to connect and route your traffic. IP-based geolocation is used only for connection routing, anti-abuse, safety/moderation, and aggregated analytics. It is not used for marketing or behavioral advertising.
4. Advertising
The Application offers optional rewarded ads through Google AdMob as a way to earn Stardust (see Section 1.7). Ads are shown only when you choose to watch one; the Application does not display banner or interstitial advertising, and does not use advertising for behavioral profiling on our side. Google AdMob is an independent advertising provider that collects and processes advertising identifiers, device information, and ad-interaction data under Google’s own privacy policy. See Section 6 for the provider link.
5. Artificial Intelligence (AI)
The Application and the Website do not currently use Artificial Intelligence (AI) technologies to process your data or to provide features. This Privacy Policy will be updated before any such feature is introduced.
6. Third-Party Services and Subprocessors
6.1 Services Operated by the Service Provider (Self-hosted)
The following categories run on infrastructure controlled by the Service Provider. They are not independent data controllers and do not transmit your data to their respective vendor companies:
Authentication (self-hosted sign-in system), product analytics, crash reporting, and the real-time backend (chat, communities, direct messages, presence, and cloud-server management) all run on open-source or self-developed services that the Service Provider self-hosts on its own infrastructure.
6.2 External Third-Party Services
The following external services are involved in providing the Application and the Website. Your data may be transmitted to or processed by these providers under their respective privacy policies:
| Provider | Purpose | Data exchanged or processed | Privacy Policy |
|---|---|---|---|
| Sign-in with Google via upstream OAuth | Email, Google account ID, OAuth tokens | https://policies.google.com/privacy | |
| Microsoft / Mojang | Validation of Xbox login chains during Minecraft player connection | Xbox login-chain data exchanged for validation (transient); selected identity fields (XUID, gamertag, Minecraft identity) are stored by us only in the cases in Sections 1.6 and 1.8 | https://privacy.microsoft.com/privacystatement |
| Google Firebase Cloud Messaging | Delivery of push notifications | Device push token, device identifier, platform, and notification payloads | https://firebase.google.com/support/privacy |
| Google AdMob | Optional rewarded ads and their verification | Advertising identifiers and ad-interaction data (collected by Google); a Byulnuri account identifier and one-time code sent to Google for reward verification, returned with an AdMob transaction identifier | https://policies.google.com/privacy |
| Cloudflare (cloud file storage) | Storage of user/community avatars, cloud-server world backups, and private moderation evidence | Avatar images, Minecraft world data, and evidence files | https://www.cloudflare.com/privacypolicy/ |
| Cloudflare (CDN / network) | CDN, DDoS protection, and TLS termination for the API, Website, and related subdomains | IP address, request headers, TLS handshake metadata | https://www.cloudflare.com/privacypolicy/ |
| Google Play Services | Android push delivery, app distribution, Play Integrity (where applicable) | As governed by Google Play Services | https://policies.google.com/privacy |
| VPS hosting provider | Server hosting for all self-hosted services above | All server-side data the Service Provider processes | (provider-specific) |
In addition to the providers above, personal data may be visible to or shared with other people as an inherent part of the service: content in public areas is visible to anyone, including signed-out visitors; content in a private galaxy or a direct message is visible to its members or the other participant; server owners can see player-administration data for their servers; and authorized staff can access data for support, safety, and moderation, as described in Section 1.
The Service Provider may also disclose information:
- as required by law, such as to comply with a subpoena, court order, or similar legal process;
- when the Service Provider believes in good faith that disclosure is necessary to protect rights, protect safety, investigate fraud, or respond to a government request;
- to service providers acting under contractual terms and documented instructions that limit their processing to providing services to the Service Provider.
7. Data Retention
- Account data (email, account ID, username, display name, bio, avatar): retained until you delete your account. Username-change records are retained as history until your account is deleted.
- Blocked device / IP / Minecraft-identity records (for hosts): retained until you, as the host, remove the block.
- Community and chat data (galaxies, channels, memberships, and the messages and direct messages you post): retained until the message, channel, galaxy, or DM thread is deleted. Deleting a channel or galaxy removes the messages it contains.
- Relayed server messages (player in-game chat, join / leave / death events with the associated Minecraft username and Xbox identifiers, plus server-status notices): retained as channel history until the linked channel or galaxy is deleted. Players cannot delete these individually.
- Read state and mention records: retained until the relevant channel is deleted or you delete your account.
- Social graph and notifications (follows, starlinks, activity records, notification inbox): follow relationships and activity records are retained until you unfollow (where applicable) or delete your account; notifications are retained until aged out, cleared, or your account is deleted.
- Push notification tokens: retained until you sign out, the token changes, or the app is uninstalled; stale/invalid tokens are cleared.
- Presence (online status): held only temporarily for the duration of your active session and never written to long-term storage.
- Cloud-server player records: session history retained approximately 90 days, then deleted; per-server records are capped and older entries pruned.
- Cloud-server world backups: automatic backups are rotated with up to 7 daily, 4 weekly, and 3 monthly copies; manual backups are retained until you delete them; a small number of pre-restore safety copies are kept. Server console output is not stored long-term.
- Stardust: your balance is retained until account deletion; transaction history is retained as a financial audit trail (de-linked from your account on deletion). Reward records for completed ads are retained for audit; unclaimed/expired rewards are removed within about a day.
- Connection-tracking records: raw IP addresses are automatically deleted after a retention period (currently 90 days) unless kept as part of an active moderation record; non-IP identity information is retained longer for moderation. Account deletion does not by itself delete all of these records (see Section 8).
- Punishment records and evidence: retained as lasting moderation history; voiding a punishment does not delete it, and evidence is kept with its record. Punishment records, IP bans, and Minecraft-identity bans can persist after account deletion because they document moderation actions and target identifiers.
- IP address (analytics and Website sign-in protection): not stored by our analytics (private addresses are filtered out entirely). Sign-in abuse-prevention uses IP addresses only briefly and does not store them.
- Analytics events, inferred approximate location, and crash logs: retained indefinitely under our current configuration. If a defined retention period (such as automatic expiry after a fixed number of months) is introduced in the future, you will be notified through an update to this Privacy Policy before it takes effect.
- Identifier for anonymous analytics sessions: rotated daily.
- Website session replays: retained for up to 30 days, then deleted automatically.
- Authentication tokens: stored on your device only (Application) or inside a secure, server-only session cookie (Website); cleared by signing out, uninstalling the Application, or clearing app/browser data.
8. Your Choices and Account Deletion
8.1 Stop data collection
Uninstalling the Application stops all device-side data collection (device identifier, analytics events, crash reports, push tokens). Signing out stops future account-linked processing but does not delete information already stored on our servers. Clearing your browser storage removes local identifiers and preferences on that browser but does not by itself erase server-side records.
8.2 Sign out
Signing out clears your authentication tokens and the locally stored analytics profile ID, and removes your push token for that device.
8.3 Account deletion
Deleting your sign-in credentials through the account self-service portal (linked from in-app settings) does not by itself delete your separate Byulnuri platform account or its associated data. Full Byulnuri account deletion is currently handled manually: there is no automated delete-account control in the Application or Website yet. To delete your Byulnuri account, submit a verified request through our Account Deletion page; submit it before deleting your sign-in credentials so we can verify ownership. Requests are processed within 14 days of receipt.
When your deletion request is processed, the following are removed:
- Your account record (email, account ID, username, display name, bio, avatar).
- Blocked device / IP / Minecraft-identity records you created as a host.
- Your follows, followers, and starlinks; your galaxy memberships, read-state, mention, notification, and activity records.
- Push notification tokens and authentication sessions/tokens registered to your account.
- Your Stardust balance and any LAN servers and cloud servers you own (including their per-server player records).
- Your staff role assignments.
The following may persist after deletion, no longer linked to your account (or, for moderation records, retained as required to keep the service safe):
- Chat messages and direct messages you posted: message content may remain as part of the channel’s or thread’s history, but the authorship link is removed. If you want specific messages erased, delete them before deleting your account, or ask us.
- Stardust transaction history: retained as a financial audit trail with the account link removed.
- Punishment records (warnings and account-level actions, IP bans, and Minecraft-identity bans): retained as lasting moderation history; neither voiding nor account deletion deletes them, and identifier-based bans may remain enforceable. Associated evidence is kept with the record.
- Connection-tracking records: account deletion does not necessarily delete these immediately. Raw IP addresses normally expire after about 90 days unless kept for active moderation, and non-IP identity signals may be kept longer to investigate abuse and prevent ban evasion.
- Moderation history where you acted as staff (e.g., punishments you issued): retained with your identifying link removed.
- Analytics and crash records: may remain for the periods stated in Section 7 after account identifiers are removed where applicable. These may still contain pseudonymous device/browser details or incidental application state and are not considered anonymous unless irreversibly de-identified. Our analytics does not store raw IP addresses; this does not by itself apply to crash reports.
- Locally stored data: the random device identifier and appearance preferences stored on your installed app or browser may remain until you uninstall the app, clear app data, or clear browser storage.
9. Security
The Service Provider provides physical, electronic, and procedural safeguards to protect information processed and maintained. Access to this information is limited to authorized personnel who need it to operate, develop, or improve the Application and the Website. Access to safety and moderation data (connection tracking, punishments, and evidence) is further restricted to staff holding the relevant permissions.
- All API and Website traffic is encrypted in transit using HTTPS (TLS 1.2 or above).
- Authentication tokens are stored on your device only (Application) or inside a secure, server-only cookie (Website), and are not exposed to web-page scripts.
- Moderation evidence files are stored privately and are accessible only to authorized staff.
- Xbox identity data is processed transiently during normal server hosting; it is stored on the Service Provider’s servers only where described in this Policy (server hosting in Section 1.6 and safety/connection tracking in Section 1.8).
Although the Service Provider endeavors to provide reasonable security for the information it processes and maintains, no security system can prevent all potential security breaches.
10. Children’s Privacy
The Service Provider does not knowingly solicit data from or market to children under the age of 13.
The Application and the Website are not directed to anyone under the age of 13. The Service Provider does not knowingly collect personally identifiable information from children under 13 years of age. If the Service Provider discovers that a child under 13 has provided personal information, that data will be deleted promptly. If you are a parent or guardian and you become aware that your child has provided personal information to the Application or the Website, please contact the Service Provider at support@byulnuri.com so that appropriate action can be taken.
11. Your Rights (GDPR for European Users)
If you are a resident of the European Economic Area (EEA), the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) and equivalent laws:
- Right of access: request a copy of the personal data the Service Provider holds about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”): request deletion of your data, subject to legal retention obligations and to legitimate moderation/safety records described in Section 1.8 and Section 8.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to restriction of processing: limit how the Service Provider uses your data.
- Right to object: object to processing based on legitimate interest, including profiling.
- Right to withdraw consent: where processing is based on your consent, withdraw it at any time.
- Right to lodge a complaint: lodge a complaint with the data-protection supervisory authority in the country where you live or work, or where you believe an infringement occurred.
Data you must provide
An email address, an internal account identifier, and a username are required to create and operate a Byulnuri account. Network and Minecraft-identity data are required when establishing LAN or cloud-server connections. Optional profile fields, push notifications, and rewarded ads are not required; declining them makes only the corresponding feature unavailable.
Legal basis for processing
The Service Provider processes your data based on:
- Contract (Art. 6(1)(b) GDPR): to create and operate an account and provide features requested by an account holder, such as messaging, communities, LAN servers, and cloud servers.
- Legitimate interest (Art. 6(1)(f) GDPR): to secure the service, prevent abuse, investigate misconduct, enforce moderation, and process the limited network and Minecraft-identity data needed when non-account participants join host-requested LAN or cloud-server sessions, and for product improvement, assessed against the affected person’s rights.
- Consent (Art. 6(1)(a) GDPR): for optional features where consent is legally required, such as enabling notifications or watching a rewarded ad.
- Legal obligation and legal claims (Art. 6(1)(c) and (f) GDPR): to comply with applicable law and to establish, exercise, or defend legal claims.
International transfers
Your data may be transferred to and processed in countries outside the EEA, including the United States (Google OAuth, Google Firebase Cloud Messaging, Google AdMob, Cloudflare, Microsoft / Xbox validation). Where required, the Service Provider relies on appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms. You may contact the privacy contact for information about the safeguards that apply.
Automated decision-making
A defined number of active warnings issued by human staff can automatically trigger an account suspension or ban. The consequence may be restricted or lost access to the service and, for a permanent ban, hiding of your public profile fields. The underlying warnings are issued by human staff. You may contact the privacy contact at hello@chungchan.dev to obtain human review, explain your position, and contest an escalation.
To exercise any of these rights, contact the privacy contact at hello@chungchan.dev.
12. How Will You Be Informed of Changes to This Privacy Policy?
This Privacy Policy may be updated from time to time. The Service Provider will post the updated policy and its effective date on this page, and will provide prominent notice of material changes where appropriate. Where a change requires your consent, we will request it before beginning the changed processing. You are advised to consult this Privacy Policy regularly.
13. Consent
The Service Provider relies on the legal bases described in Section 11. Where the law requires consent for specific processing (such as non-essential analytics, session replay, or advertising-related identifiers), that processing is subject to the applicable consent requirement, and merely using the service is not treated as consent where an affirmative choice is legally required. In this Policy, “processing” means using cookies or local storage on a device, or using, storing, deleting, combining, or disclosing information in any way.
14. Contact
For privacy questions or to exercise your rights, contact the privacy contact at hello@chungchan.dev. For general support, email support@byulnuri.com.
15. Effective Date
This Privacy Policy is effective as of 2026-07-18.